æè¿ãSSLãšTLSã«é¢é£ããé倧ãªè匱æ§ãããã€ãçºèŠãããŠããŸããå€ãã®ãŠãŒã¶ã¯ãã·ã¹ãã äžã§äœ¿çšãããŠããSSLãšTLSã®ããŒãžã§ã³ã確èªããæ¹æ³ãç¥ããŸããã仿¥ã¯ãTLSïŒTransport Layer SecurityïŒãšSSLïŒSecure Sockets LayerïŒã®åºæ¬çãªä»çµã¿ã«ã€ããŠèª¬æããŸãã
SSLã¯TLSã®å身ã§ããããããX.509èšŒææžã䜿çšããé察称æå·åãšåŒã°ããŸãã仿¥ã¯ãé察称æå·åãšå¯Ÿç§°æå·åã«ã€ããŠèª¬æããŸãã
察称æå·åã¯ãæå·åæ¹åŒãšããŠã¯æãå€ãæ¹æ³ã§ãããæå·åãšåŸ©å·åã«åãããŒã䜿çšããŸããããšãã°ãã¢ã«ãã¡ãããã®æåã察称ããŒã«äœ¿ããäœçœ®ãããã€ãç§»åããã ããšãã£ãã·ã³ãã«ãªæ¹æ³ããããŸããã§ã¯ãéåžžã«ã·ã³ãã«ãªå¯Ÿç§°æå·åã®äŸã玹ä»ããŸãããããhey the redcoats are comingããšããã¡ãã»ãŒãžãéä¿¡ãããå Žåããmjceyljewjihtfyxefwjehtrnslããšããã¡ãã»ãŒãžãéä¿¡ããŸãããã®ã¡ãã»ãŒãžã¯ãã5ããšããããŒã䜿ã£ãŠåŸ©å·åã§ããŸããã5ãã¯ããã¢ã«ãã¡ãããã®æåã5ã€ããããããšãæå³ããŸãã
ã€ãŸããAã¯FãBã¯GãCã¯HããšãªããŸããã¢ã«ãã¡ãããã®æåŸã«ç©ºçœæåã远å ããã°ãæå·æãããã«è€éã«ãªããŸããYã¯Dã§ã¯ãªãCã«ãªããç©ºçœæåãEã«ãªããŸããEããã¹ãŠç©ºçœæåã«ãããšããã®ããã«ãªããŸãã
mjceyljewjihtfyxefwjehtrnsl
mjc ylj wjihtfyx fwj htrnsl
hey the redcoats are coming
ã¢ã«ãã¡ãããã®å€æïŒäžç·ã¯ç©ºçœæåïŒ
察称æå·åã®åé¡ç¹ã¯ãã¡ãã»ãŒãžã埩å·åããã«ã¯ããŒãéä¿¡ããªããã°ãªããªãç¹ã§ããããŒãçãã°ã誰ã§ãã¡ãã»ãŒãžã埩å·åã§ããŠããŸããŸãã
ãã®ãªã¹ã¯ã軜æžããæ¹æ³ãšããŠèæ¡ãããã®ããé察象æå·åã§ããé察象æå·åã¯ãå ¬éããŒãšãåŒã°ããŸãããã®æå·æ¹åŒã§ã¯ãå¹³æã®æå·åã«ããŒã2ã€äœ¿çšããŸãã1ã€ã¯å ¬éããããŒã§ããããã1ã€ã¯ç§å¯ã®ããŒã§ããå ¬éããŒã¯ãããã¹ãã®æå·åã«äœ¿çšããŸãããããŠãå ¬éããŒã«å¯Ÿå¿ããç§å¯ããŒããªããšã埩å·åã§ããŸããã
é察称æå·åã§ã¯ãéä¿¡è ãšåä¿¡è ãå ¬éããŒã亀æããŸããæå·åã«ã¯ãçžæã®å ¬éããŒã䜿çšãã埩å·åã«ã¯èªåã®ç§å¯ããŒã䜿çšããŸãã
ãã®æ¹åŒã§ã¯ã埩å·åã«äœ¿çšããããŒã¯ãã§ã«æå ã«ããã®ã§ãããŒã亀æããå¿ èŠããããŸãããèªåãéã£ãå ¬éããŒã§æå·åãããã¡ãã»ãŒãžãèªåã®ç§å¯ããŒã§åŸ©å·åããã®ã§ãã¡ãã»ãŒãžãä»äººã«èªãŸããŠããŸãå±éºã¯ãããŸããããŸããç§å¯ããŒã§ã¡ãã»ãŒãžãæå·åããå ¬éããŒã§åŸ©å·åããããšãå¯èœã§ãããã®ããã«ãæå·åãäžæ¹åã§è¡ãããããšããããé察称ããšããååãä»ããããŠããŸãã
çŸåšãã³ã³ãã¥ãŒã¿ã§ã¯åŒ·åãªãã«ãŒããã©ãŒã¹æ»æãå¯èœã«ãªã£ãŠããã®ã§ãããªãé«åºŠãªã¢ã«ãŽãªãºã ã䜿ã£ãŠçæãããè€éãªããŒã䜿çšãããŠããŸãã
SSLãšTLSã¯ãè€æ°ã®æå·åæ¹åŒïŒã¢ã«ãŽãªãºã ïŒã䜿ã£ãŠå ¬éããŒãšç§å¯ããŒã®ãã¢ãçæã§ããŸããRC4ã¯åŒ±ãæå·æ¹åŒã®1ã€ã§ãããæå¹ãªããŒã¿ä¿è·æ¹æ³ã§ã¯ãããŸãããããããSSL v3.0ããå§ãããªãçç±ã§ããRC4-SHAã¯ãSSL v.3.0ã¹ã€ãŒãã§äœ¿çšã§ããæãé«åºŠãªæå·åæ¹åŒã§ãã
ããã«å¯ŸããŠãAESã¯åŒ·åãªæå·æ¹åŒã§ãããTLS v1.0ãTLSv.1.1ïŒv.1.2ã§äœ¿çšã§ããŸãã䜿çšå¯èœãªæå·æ¹åŒãšãã®åŒ·åºŠããã§ãã¯ããã«ã¯ãLinuxã³ãã³ãã©ã€ã³ã§æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
#openssl ciphers -v 'ALL:!ADH:@STRENGTH'
SSLãšTLSã®è§£èª¬ Frank Dreamer
2015幎07æ22æ¥
æè¿ãSSLãšTLSã«é¢é£ããé倧ãªè匱æ§ãããã€ãçºèŠãããŠããŸããå€ãã®ãŠãŒã¶ã¯ãã·ã¹ãã äžã§äœ¿çšãããŠããSSLãšTLSã®ããŒãžã§ã³ã確èªããæ¹æ³ãç¥ããŸããã仿¥ã¯ãTLSïŒTransport Layer SecurityïŒãšSSLïŒSecure Sockets LayerïŒã®åºæ¬çãªä»çµã¿ã«ã€ããŠèª¬æããŸãã
SSLã¯TLSã®å身ã§ããããããX.509èšŒææžã䜿çšããé察称æå·åãšåŒã°ããŸãã仿¥ã¯ãé察称æå·åãšå¯Ÿç§°æå·åã«ã€ããŠèª¬æããŸãã
察称æå·åã¯ãæå·åæ¹åŒãšããŠã¯æãå€ãæ¹æ³ã§ãããæå·åãšåŸ©å·åã«åãããŒã䜿çšããŸããããšãã°ãã¢ã«ãã¡ãããã®æåã察称ããŒã«äœ¿ããäœçœ®ãããã€ãç§»åããã ããšãã£ãã·ã³ãã«ãªæ¹æ³ããããŸããã§ã¯ãéåžžã«ã·ã³ãã«ãªå¯Ÿç§°æå·åã®äŸã玹ä»ããŸãããããhey the redcoats are comingããšããã¡ãã»ãŒãžãéä¿¡ãããå Žåããmjceyljewjihtfyxefwjehtrnslããšããã¡ãã»ãŒãžãéä¿¡ããŸãããã®ã¡ãã»ãŒãžã¯ãã5ããšããããŒã䜿ã£ãŠåŸ©å·åã§ããŸããã5ãã¯ããã¢ã«ãã¡ãããã®æåã5ã€ããããããšãæå³ããŸãã
ã€ãŸããAã¯FãBã¯GãCã¯HããšãªããŸããã¢ã«ãã¡ãããã®æåŸã«ç©ºçœæåã远å ããã°ãæå·æãããã«è€éã«ãªããŸããYã¯Dã§ã¯ãªãCã«ãªããç©ºçœæåãEã«ãªããŸããEããã¹ãŠç©ºçœæåã«ãããšããã®ããã«ãªããŸãã
mjceyljewjihtfyxefwjehtrnsl
mjc ylj wjihtfyx fwj htrnsl
hey the redcoats are coming
ã¢ã«ãã¡ãããã®å€æïŒäžç·ã¯ç©ºçœæåïŒ
察称æå·åã®åé¡ç¹ã¯ãã¡ãã»ãŒãžã埩å·åããã«ã¯ããŒãéä¿¡ããªããã°ãªããªãç¹ã§ããããŒãçãã°ã誰ã§ãã¡ãã»ãŒãžã埩å·åã§ããŠããŸããŸãã
ãã®ãªã¹ã¯ã軜æžããæ¹æ³ãšããŠèæ¡ãããã®ããé察象æå·åã§ããé察象æå·åã¯ãå ¬éããŒãšãåŒã°ããŸãããã®æå·æ¹åŒã§ã¯ãå¹³æã®æå·åã«ããŒã2ã€äœ¿çšããŸãã1ã€ã¯å ¬éããããŒã§ããããã1ã€ã¯ç§å¯ã®ããŒã§ããå ¬éããŒã¯ãããã¹ãã®æå·åã«äœ¿çšããŸãããããŠãå ¬éããŒã«å¯Ÿå¿ããç§å¯ããŒããªããšã埩å·åã§ããŸããã
é察称æå·åã§ã¯ãéä¿¡è ãšåä¿¡è ãå ¬éããŒã亀æããŸããæå·åã«ã¯ãçžæã®å ¬éããŒã䜿çšãã埩å·åã«ã¯èªåã®ç§å¯ããŒã䜿çšããŸãã
ãã®æ¹åŒã§ã¯ã埩å·åã«äœ¿çšããããŒã¯ãã§ã«æå ã«ããã®ã§ãããŒã亀æããå¿ èŠããããŸãããèªåãéã£ãå ¬éããŒã§æå·åãããã¡ãã»ãŒãžãèªåã®ç§å¯ããŒã§åŸ©å·åããã®ã§ãã¡ãã»ãŒãžãä»äººã«èªãŸããŠããŸãå±éºã¯ãããŸããããŸããç§å¯ããŒã§ã¡ãã»ãŒãžãæå·åããå ¬éããŒã§åŸ©å·åããããšãå¯èœã§ãããã®ããã«ãæå·åãäžæ¹åã§è¡ãããããšããããé察称ããšããååãä»ããããŠããŸãã
çŸåšãã³ã³ãã¥ãŒã¿ã§ã¯åŒ·åãªãã«ãŒããã©ãŒã¹æ»æãå¯èœã«ãªã£ãŠããã®ã§ãããªãé«åºŠãªã¢ã«ãŽãªãºã ã䜿ã£ãŠçæãããè€éãªããŒã䜿çšãããŠããŸãã
SSLãšTLSã¯ãè€æ°ã®æå·åæ¹åŒïŒã¢ã«ãŽãªãºã ïŒã䜿ã£ãŠå ¬éããŒãšç§å¯ããŒã®ãã¢ãçæã§ããŸããRC4ã¯åŒ±ãæå·æ¹åŒã®1ã€ã§ãããæå¹ãªããŒã¿ä¿è·æ¹æ³ã§ã¯ãããŸãããããããSSL v3.0ããå§ãããªãçç±ã§ããRC4-SHAã¯ãSSL v.3.0ã¹ã€ãŒãã§äœ¿çšã§ããæãé«åºŠãªæå·åæ¹åŒã§ãã
ããã«å¯ŸããŠãAESã¯åŒ·åãªæå·æ¹åŒã§ãããTLS v1.0ãTLSv.1.1ïŒv.1.2ã§äœ¿çšã§ããŸãã䜿çšå¯èœãªæå·æ¹åŒãšãã®åŒ·åºŠããã§ãã¯ããã«ã¯ãLinuxã³ãã³ãã©ã€ã³ã§æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
openssl ciphers -v 'ALL:!ADH:@STRENGTH'
SSLãšTLSã®ããŒãžã§ã³ã¯æ¬¡ã®é åºã§é²åããŠããŸããã
⢠SSL v. 1.0
⢠SSL v. 2.0
⢠SSL v. 3.0
⢠TLS v. 1.0
⢠TLS v. 1.1
⢠TLS v. 1.2
⢠TLS v. 1.3ïŒçŸåšãã©ããçïŒ
ããŒãžã§ã³ãæ°ãããªãã»ã©æå·åæ¹åŒãæ°ãããªããæ§ããŒãžã§ã³ã§ã¯äœ¿çšã§ããªãã£ãããŒãµã€ãºã䜿çšã§ããããã«ãªã£ãŠããŸããSSLãšTLSã§ã¯ãè€æ°ã®ããŒãžã§ã³ã§åãæå·åæ¹åŒãæäŸãããŠããŸãã
SSLèšŒææžã¯ãã¡ãã»ãŒãžã®æå·åããä¿¡é Œã®ç¢ºç«ãŸã§ãããŸããŸãªçšéã«äœ¿çšãããŸãã
äžèšã§èª¬æããããã«ãSSL/TLSãšã¯ãå ¬éããŒãŸãã¯ç§å¯ããŒã®ããããã§ã¡ãã»ãŒãžãæå·åããããäžæ¹ã®ããŒã䜿ã£ãŠåŸ©å·åããã·ã³ãã«ãªæ¹æ³ã§ãã
Webãµã€ããä¿¡é Œã§ãããã©ããã倿ããæ¹æ³ã«ã¯ãèšŒææžã䜿çšãããŸããä¿¡é Œé¢ä¿ã®ç¢ºç«ã«ã¯ãä¿¡é Œã®ãã§ãŒã³ãæ§ç¯ããå¿ èŠãããããããæ åœããã®ãèªèšŒå±ïŒCAïŒã§ããèªèšŒå±ã¯ããããã¯ãŒã¯äžã®ãµãŒããŸãã¯ç¬¬äžè CAã§ãããã¡ã€ã³CAãçºè¡ããèšŒææžã®ä¿¡é Œæ§ã¯ãããŒã«ã«ãã¡ã€ã³å ã®ã¿ã§ä¿èšŒãããŸããå€éšã«åããWebã€ã³ã¿ãŒãã§ã€ã¹ã®ä¿¡é Œãä¿èšŒããã«ã¯ãWWWãã¡ã€ã³ãèªèšŒããèªå®ãåãã第äžè CAãçºè¡ããèšŒææžãå¿ èŠã«ãªããŸããCAã¯ãããããããã®æ£åœæ§ã蚌æãããã«ãŒãèšŒææžããæã£ãŠããŸããä¿¡é Œé¢ä¿ã®ç¢ºç«ã§ã¯ãCAã®ã«ãŒãèšŒææžãæ ãæãšãªããŸããã«ãŒãèšŒææžããšã«äžéCAã«ãŒãèšŒææžïŒICAïŒãäœæãããããã«ãã£ãŠä¿¡é Œã®éå±€æ§é ãæ§ç¯ãããŸãããã®ãã§ãŒã³ã®æ«ç«¯ã«ããã®ãããçœ²åæžã¿èšŒææžãã§ãããã®èšŒææžã«ãããWebäžã§HTTPãåŠçããããã€ã¹ãèå¥ãããŸãã
以äžã¯ã.pem圢åŒã«å«ãŸãããã§ãŒã³ãã³ãã«å šäœã瀺ããŠããŸããä¿¡é Œã®ãã§ãŒã³ã¯ããã§ãŒã³ãã³ãã«ã®äžããäžãžãšã€ãªãã£ãŠããŸãã
SSLãšTLSã§ã¯ãæå·åã¹ã€ãŒããæ¥åèŠçã«éžæãããŸããã€ãŸããæ¥ç¶ã®çžæåŽã§äœ¿çšã§ããæå·åæ¹åŒã®ãã¡ã匷床ãæãé«ããã®ã䜿çšãããŸãããããã¯ãŒã¯éä¿¡ã§åŒ±ãæå·åæ¹åŒã䜿çšãããŠããå Žåã¯ãæ¥ç¶ã®äž¡ç«¯ã§äœ¿çšã§ããæå·åæ¹åŒã確èªããŠãã ããã
SSLæ¥ç¶ã®ç¢ºèªïŒHTTPSïŒïŒ
#openssl s_client -connect :443 -showcerts
TLSã䜿çšããã¡ãŒã«ãµãŒãã®ç¢ºèªïŒ
#openssl s_client -connect :25 -starttls smtp -showcerts
ãã©ã¯ãŒããããã¯ãŒã¯ã¹ã®ã客æ§ã®äžã«ã¯ã匷床ã®é«ãæå·æ¹åŒãèšå®ãããŠããã«ãããããããå®éã«ã¯åŒ±ãæ¹åŒã䜿çšãããŠããã±ãŒã¹ããããŸãããã®ãããªå Žåã«ã¯ãæ¥ç¶ã®äž¡ç«¯ã®ã€ã³ã¿ãŒãã§ã€ã¹ããã§ãã¯ããŠãã ãããã€ãŸããèªåã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒãŸãã¯é¡§å®¢ã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒããã§ãã¯ããããã«çžæã®ã€ã³ã¿ãŒãã§ã€ã¹ããã§ãã¯ããå¿ èŠããããŸããSSLãšTLSã¯æ¥åèŠçãªæå·æ¹åŒãªã®ã§ãéä¿¡ã®äž¡ç«¯ã§äœ¿çšã§ããæ¹åŒã®ãã¡ã匷床ãæãé«ããã®ãæ¡çšããŸãã
ããšãã°ãèªåã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯TLS v.1.2ã®AES256-SHAã䜿çšå¯èœã§ãã£ãŠããçžæåŽã¯SSL v3.0ã®RC4-SHAã«ãã察å¿ããŠããªãå¯èœæ§ããããŸãããã®å Žåãäž¡ç«¯ã§æã匷床ã®é«ãæå·æ¹åŒã䜿çšããŠéä¿¡ãè¡ãããŸãã
以äžã«ãSSLã€ã³ã¿ãŒãã§ã€ã¹ã®opensslã¯ãšãªã®äŸã瀺ããŸãã
openssl s_client -connect 24.97.125.194:443 -showcerts
CONNECTED(00000003)
depth=0 /C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
verify error:num=18:self signed certificate
verify return:1
depth=0 /C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
verify return:1
Certificate chain
0 s:/C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
i:/C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
-----BEGIN CERTIFICATE-----
MIICjDCCAfWgAwIBAgIEU9cMJDANBgkqhkiG9w0BAQUFADBxMQswCQYDVQQGEwJV
(certificate abbreviated for space constraints)
-----END CERTIFICATE-----
Server certificate
subject=/C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
issuer=/C=US/O=Barracuda Networks, Inc/CN=Barracuda Firewall X400/ST=CA/L=Campbell
No client certificate CA names sent
SSL handshake has read 828 bytes and written 355 bytes
New, TLSv1/SSLv3, Cipher is AES256-SHA
Server public key is 1024 bit
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : AES256-SHA
Session-ID: 4E36015736D7DF91A4459D4C8E8D31D05B6D5BD5318185024026AFC5A643709F
Session-ID-ctx:
Master-Key: A6579CBB82C2B62626FCF82B7A15781C17887BF74B4AB4796B87FD24C25F59009CEFCE574868BB8D67E2BFBD083F2146
Key-Arg : None
Krb5 Principal: None
Start Time: 1415288412
Timeout : 300 (sec)
Verify return code: 18 (self signed certificate)
äžèšã®SSLèšŒææžã¯TLS v.1ã䜿çšããæãé«ãæå·åŒ·åºŠã¯AES256-SHAã§ãããã®èšŒææžã¯ãSSL v.3ã§å¯Ÿå¿ã§ããæå·åæ¹åŒãšã®ããŽã·ãšãŒã·ã§ã³ãå¯èœã§ããèªå·±çœ²åèšŒææžã§ãããå ¬éããŒã¯1024ãããã§ãã
ãã©ã¯ãŒããããã¯ãŒã¯ã¹ã®ãœãªã¥ãŒã·ã§ã³ã®SSLãšTLSã«é¢ããã質åã¯ããµããŒãéšéã«ãé»è©±ãŸãã¯ãµããŒããã±ããã§ãåãåãããã ããã
ã質åããåŸ ã¡ããŠãããŸãã
â»æ¬å 容ã¯Barracuda Product Blog 2015幎7æ9æ¥SSL and TLS Explainedã翻蚳ãããã®ã§ãã
Frank Dreamer
æ¬çš¿ã¯ããã©ã¯ãŒããããã¯ãŒã¯ã¹ã®Webãµã€ãã«æ²èŒãããŠããããã©ã¯ãŒãã©ãã7æ22æ¥ä»ã®èšäºã®è»¢èŒã§ãã


